Listen to this Post
How the mentioned CVE works:
The CVE-2021-42013 vulnerability is a path traversal and remote code execution flaw in Apache HTTP Server versions 2.4.49 and 2.4.50. The vulnerability arises from an insufficient fix for CVE-2021-41773. The core issue lies in a path normalization error in the `ap_normalize_path()` function. When the `mod_cgi` module is enabled and the “require all denied” configuration is not set, an attacker can craft a malicious URL containing encoded path traversal sequences, such as `.%2e/` or %%32%65/. These sequences bypass the security checks implemented to address the previous CVE. A specially crafted request, for example, to /cgi-bin/..%%32%65/..%%32%65/..%%32%65/..%%32%65/bin/sh, can escape the document root. This allows the attacker to map the URL to files outside the expected directories. If the traversed path targets a CGI script, the server will execute the script with the privileges of the web server daemon, leading to arbitrary command execution on the underlying host.
Platform: Apache HTTP Server
Version: 2.4.49-50
Vulnerability : Path Traversal
Severity: Critical
date: 2021-10-07
Prediction: Patch Available
What Undercode Say:
curl -H "User-Agent: () { :; }; echo; /bin/cat /etc/passwd" http://vulnerable.host/cgi-bin/attack.cgi
nmap -sV --script http-vuln-cve2021-42013 <target>
grep -r "Require all denied" /etc/apache2/
// Example of a malicious request path char exploit_path = "/cgi-bin/..%%32%65/..%%32%65/..%%32%65/..%%32%65/etc/passwd";
How Exploit:
Craft malicious URLs.
Bypass path normalization.
Execute system commands.
Protection from this CVE
Update to 2.4.51.
Implement “Require all denied”.
Disable unused CGI scripts.
Impact:
Remote Code Execution.
Information Disclosure.
System Compromise.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

